Vulnerabilities (CVE)

Filtered by vendor Hyperdown Project Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25849 1 Hyperdown Project 1 Hyperdown 2025-05-09 N/A 5.4 MEDIUM
The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.